Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.7VMware Updated

High [CVE-2026-41012] BOSH: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and…

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. An attacker who can intercept traffic between the BOSH Director and vCenter can establish a malicious server impersonating the vCenter REST API. When the BOSH Director makes CPI calls to perform routine cloud infrastructure operations, the attacker captures the vCenter administrator username and password transmitted via HTTP Basic authentication. The vulnerability stems from insufficient authentication security in the communication protocol between BOSH Director and vCenter. While HTTPS may be used, the lack of proper certificate validation and pinning allows attackers to successfully impersonate vCenter endpoints. Because vCenter credentials typically grant full administrative control over the entire virtualization estate, successful credential capture yields complete takeover of every VM, datastore, and network the CPI manages. This exposure exists on every CPI call (including routine deployment operations, not just when tags are configured) and cannot be mitigated by supplying a CA certificate alone. Affected product named by the advisory: bosh-vsphere-cpi-release.

CVE-2026-41012
ESXiTanzu / SpringvSphere
Aug 29, 2026
High7.6VMware Updated

High [CVE-2026-59284] Spring Cloud: There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled.

There is no allow list for property keys when Spring Cloud Commons writable /actuator/env is enabled. Spring Cloud Commons 3.1.10 and earlier

CVE-2026-59284
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-59282] Spring Framework: Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths ont…

Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 5.2.25.RELEASE and earlier

CVE-2026-59282
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47893] Spring Framework: Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by…

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47893
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47889] Spring Framework: WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite…

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47889
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47888] Spring Framework: Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47888
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47886] Spring Framework: Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial…

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47886
Tanzu / Spring
Aug 27, 2026
High7.5VMware Updated

High [CVE-2026-47885] Spring Framework: The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set t…

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8

CVE-2026-47885
Tanzu / Spring
Aug 27, 2026
High7.7VMware Updated

High [CVE-2026-47879] Spring Cloud: Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto…

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 3.1.13 and earlier

CVE-2026-47879
Tanzu / Spring
Aug 27, 2026
High8.2VMware Updated

High [CVE-2026-47877] Spring Security: Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding.

CVE-2026-47877
Tanzu / Spring
Aug 27, 2026
High7.4VMware Updated

High [CVE-2026-47841] Spring Security: application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a di…

An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store.

CVE-2026-47841
Tanzu / Spring
Aug 26, 2026
High7.2VMware Updated

High [CVE-2026-47836] Spring Cloud: The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repos…

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.14 and earlier

CVE-2026-47836
Tanzu / Spring
Aug 26, 2026
High7.4VMware Updated

High [CVE-2026-41707] Spring Security: Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwt…

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict legitimate entries by flooding the server with dummy requests, then replay intercepted valid DPoP proofs. This issue affects Spring Security: 7.1.0, from 7.0.0 through 7.0.6, and from 6.5.0 through 6.5.11.

CVE-2026-41707
Tanzu / Spring
Aug 25, 2026
High7.5VMware

High [CVE-2026-47827] BOSH: Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell co…

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

CVE-2026-47827
Tanzu / Spring
Aug 21, 2026
High7.6VMware

High [CVE-2026-41703] Out-of-bounds read vulnerability

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.

CVE-2026-41703
ESXiCloud FoundationWorkstation & FusionvSphere
Jul 30, 2026
High8.3VMware

High [CVE-2026-47882] Spring Boot: When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud F…

When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47882
Tanzu / Spring
Jul 30, 2026
High8.0VMware

High [CVE-2026-47858] Spring Boot: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applic…

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

CVE-2026-47858
Tanzu / Spring
Jul 30, 2026
High8.8VMware

High [CVE-2026-47871] Avi Load Balancer: VMware Avi Load Balancer contains a directory traversal vulnerability.

VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, authenticated network users to perform directory traversal attacks.

CVE-2026-47871
Avi / VeloCloud
Jul 18, 2026
High7.1VMware

High [CVE-2026-47870] Avi Load Balancer: VMware Avi Load Balancer contains a privilege escalation vulnerability.

VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code.

CVE-2026-47870
Avi / VeloCloud
Jul 18, 2026
High8.7VMware

High [CVE-2026-47869] Avi Load Balancer: VMware Avi Load Balancer contains a remote code execution vulnerability.

VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code.

CVE-2026-47869
Avi / VeloCloud
Jul 18, 2026